This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
YahavLevin
YahavLevin Beginner
Beginner
since ‎2013-05-08
‎2021-04-10

User Statistics

  • 18 Posts
  • 2 Solutions
  • 4 Likes given
  • 5 Likes received
Announcement Banner

Users are unable to open Netwitness Support Cases via email. Please open support cases via portal or by phone

View Details
  • NetWitness Community
  • About YahavLevin

User Activity

  • Posts
  • Replies

[SA-IM] How to add "Raw Event / Alert" into the SA-IM event table (json script)

by YahavLevin 2016-02-03 general.in NetWitness Discussions
2016-02-03
Hello, Today i tried to do so, following by the value i saw in the UCF xmlit looked like"generic.rawalert" I tried adding it to the JSON script and for some reason, it just stopped the SA-IM from receiving incidents the reason why i did that was beca...

Maximizing SA-IM meta fields in event view

by YahavLevin 2016-01-26 general.in NetWitness Discussions • latest reply by YahavLevin 2016-01-28
2016-01-26
Hello,I'm very frustrated with trying to connect SA-IM 10.5.x to Archer SecOps 1.3I'm stuck on SA side which i have to add the relevant meta keys to the SA-IM JSON Script that sits at opt/rsa/im/scripts/core-alerts.jsI tried adding JSON lines for new...

Re: Maximizing SA-IM meta fields in event view

by YahavLevin 2016-01-28 general.in NetWitness Discussions
2016-01-28
On the sa that i'm working (its a bank prod sa) we got around 2000 incidents thats why its so fast

Re: Maximizing SA-IM meta fields in event view

by YahavLevin 2016-01-28 general.in NetWitness Discussions • latest reply by DavidWaugh1 2016-01-28
2016-01-28
I'm literally speechless,i didn't see this file and i literally downloaded every SecOps 1.3 file that i could find (on this page that you shared as well) I just investigated the whole thing to understand the new UCF and SA alone, and i was only stuck...

Re: Maximizing SA-IM meta fields in event view

by YahavLevin 2016-01-28 general.in NetWitness Discussions
2016-01-28
Yep David you're totally rightBy the way I tested it and it worked which is why i posted it so everyone can be sure 100% about the process Hope you had a great meal with Leon, happy weekend !

Re: Maximizing SA-IM meta fields in event view

by YahavLevin 2016-01-28 general.in NetWitness Discussions • latest reply by DavidWaugh1 2016-01-28
2016-01-28
So, support helped me with that (Archer support) basically you have to edit : opt/rsa/im/scripts/normalize_core_alerts.jsand add lines such as : category: Utils.stringValue(event.category), action: Utils.stringValue(event.action), event_source: Utils...
Likes from
User Count
Anonymous
1
jeffshurtliff
Administrator jeffshurtliff Administrator
2
YahavLevin
YahavLevin Beginner
1
DavidWaugh1
Employee DavidWaugh1
1
View all
Likes given to
User Count
DavidWaugh1
Employee DavidWaugh1
3
YahavLevin
YahavLevin Beginner
1
View all
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.